every model spec’d & versioned · Concordance-tested changelog →
Legal

Privacy Policy

Effective Date: August 28, 2026

This Privacy Policy explains how Worthune collects, uses, stores, and protects your information. This policy is structured to align with U.S. privacy expectations, CCPA-style disclosures, and GDPR-ready standards.

1.Information We Collect

A. Information You Provide

  • Name and email address
  • Login credentials
  • Newsletter preferences
  • Scenario tool inputs
  • FinFounders tool state and named versions
  • Activity log of account actions (saves, updates, plan changes)
  • Financial assumptions and planning variables
  • Account profile information

B. Automatically Collected Data

  • IP address and browser type
  • Device identifiers
  • Session activity and pages viewed
  • Timestamps and referral URLs
  • Cookie identifiers

2.Scenario and Computation Processing

We use the inputs you provide to compute scenario outputs — projections, comparisons, simulations, and decision-strategy results. Numeric outputs are produced by deterministic computation engines, not by a language model: the same inputs always produce the same outputs, and simulations run from stated seeds. Where AI assists elsewhere in the product (for example, explaining a result or drafting an import mapping), it never sits in the numeric path, and such processing may use third-party infrastructure providers or internal systems.

3.Data Retention

We retain account and scenario data while your account remains active, and for up to five (5) years after account cancellation, or longer if required by law, dispute resolution, fraud prevention, or legal compliance. Users may request deletion subject to legal retention obligations.

FinFounders tool state (auto-saved drafts and named versions) is scoped to your user account and visible only to you. Deleting a saved version soft-deletes it immediately; soft-deleted rows are permanently purged after 30 days and cannot be recovered.

Your account activity log — a chronological record of saves, updates, and plan changes viewable at /activity — is scoped to your user account and visible only to you. Activity entries are retained alongside the account and removed when the account is deleted.

Platform customer data — household records, import batches, webhook endpoint configuration, and white-label tenant configuration submitted through the API — is retained for as long as your organization’s account is active or until you delete it through the API. Archiving or deleting a household through the API removes it from active processing; closing the account removes the organization’s stored platform data, subject to the legal retention obligations above.

4.Newsletter and Marketing Communications

If you subscribe to updates, we may send newsletters, product updates, educational content, and feature announcements. Email delivery may be handled through Resend. Every marketing email includes an unsubscribe mechanism.

6.Your Rights

Depending on your jurisdiction, you may request:

  • Access to personal data
  • Correction of inaccurate data
  • Deletion of personal data
  • Export / portability
  • Withdrawal of consent
  • Restriction of processing

This framework aligns with CCPA-style and GDPR-style rights.

7.Data Sharing

We do not sell personal data. We may share data with:

  • Hosting providers
  • Analytics providers
  • Email service providers
  • Legal authorities when required
  • Fraud prevention vendors

8.Security

We implement commercially reasonable safeguards. However, no digital system is completely secure.

9.International Users

If you access the Services from outside the United States, you consent to transfer and processing in the United States.

10.API and Platform Data

The API has two modes with different data practices. Stateless model calls (the calculator models, claim verification, grading, and reports) are processed to compute and return outputs and to operate, secure, meter, and improve the Services; their inputs are not stored. They are designed for numeric planning values — do not submit data identifying a specific individual through the stateless model endpoints.

The household engine and white-label services store data at our customers’ instruction. Household records (members, accounts, incomes, expenses), import batches, webhook endpoint configuration, and tenant branding configuration are submitted by our business customers and may include personal data of their end clients. The customer controls that data: we process it solely to provide, secure, meter, and support the Services, we do not sell it, we do not use it to train models, and we do not use it to build profiles of end clients. Customers can delete it at any time through the API or by closing their account. End clients of a Worthune customer should direct data requests to that customer, who controls the records; we assist customers with such requests.

We collect aggregate, low-cardinality usage telemetry (daily counts per endpoint and model — no IP addresses, user agents, or input values) and publish the same aggregates at /api/v1/telemetry. Calls authenticated with an API key are additionally counted per key at the same daily-count granularity, so paid accounts can see their own usage at /console; these per-key counts are visible only to the key holder. Paid accounts additionally store the billing details our payment processor (Stripe) provides and a hash of each issued API key; we never store card numbers or plaintext keys.

11.Contact for Privacy Requests

For privacy requests, contact us at support@worthune.com.